Outlier sequence detection method and device

By generating frequency domain data of one-dimensional time series data, determining the data period using frequency features, converting it into two-dimensional time series data, and extracting time series features, the problem of accuracy in system anomaly detection is solved, and more efficient operation and maintenance anomaly detection is achieved.

CN121502579APending Publication Date: 2026-02-10CHINA MOBILE GRP BEIJING +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511530822.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing technologies are prone to missed or false detections when the detection system malfunctions, resulting in insufficient detection accuracy.

Method used

By acquiring the system's operation and maintenance indicators, frequency domain data of one-dimensional time series data is generated. The frequency characteristics of the target frequency components in the frequency domain data are used to determine the data period. The one-dimensional time series data is then converted into two-dimensional time series data. The time series features of the two-dimensional time series data are extracted as classification features. Finally, outlier time series data are determined based on the classification results.

Benefits of technology

It improves the accuracy of system anomaly detection, enabling accurate detection of outlier time-series data and enhancing the ability to generate operational anomaly information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121502579A_ABST
    Figure CN121502579A_ABST
Patent Text Reader

Abstract

Embodiments of the invention provide an outlier sequence detection method and apparatus. The method comprises the steps of obtaining an operation and maintenance index of a to-be-detected system; the operation and maintenance index comprises a plurality of one-dimensional time sequence data; for each piece of one-dimensional time sequence data, generating frequency domain data of the one-dimensional time sequence data, and determining a data period of the one-dimensional time sequence data according to frequency characteristics of a target frequency component in the frequency domain data; for each piece of one-dimensional time sequence data, converting the one-dimensional time sequence data into two-dimensional time sequence data according to a data period, and extracting time sequence characteristics of the two-dimensional time sequence data as classification characteristics of the one-dimensional time sequence data; classifying the one-dimensional time series data according to the classification features of the one-dimensional time series data, and determining outlier time series data in the one-dimensional time series data according to a classification result; the outlier time sequence data is used for generating operation and maintenance abnormal information of the to-be-detected system. According to the embodiment, the accuracy of detecting the system abnormity can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of operation and maintenance technology, and in particular to a method and device for detecting outlier sequences. Background Technology

[0002] In related technologies, system operation and maintenance indicators can be used to determine whether a system is experiencing operational anomalies. However, with the development of internet technology, systems are becoming increasingly large-scale and their operation and maintenance indicators are becoming more complex. Relying on these indicators for system anomaly detection may lead to missed or false positives. Therefore, improving the accuracy of system anomaly detection is one of the problems that needs to be addressed. Summary of the Invention

[0003] This disclosure provides a method and apparatus for detecting outlier sequences to address the problem of improving the accuracy of anomaly detection in a system.

[0004] In a first aspect, embodiments of this disclosure provide a method for detecting outlier sequences, including: Obtain the operation and maintenance indicators of the system to be tested; the operation and maintenance indicators include multiple one-dimensional time-series data. For each of the one-dimensional time series data, frequency domain data of the one-dimensional time series data is generated, and the data period of the one-dimensional time series data is determined according to the frequency characteristics of the target frequency component in the frequency domain data. For each of the one-dimensional time series data, the one-dimensional time series data is converted into two-dimensional time series data according to the data period, and the time series features of the two-dimensional time series data are extracted as the classification features of the one-dimensional time series data. Based on the classification characteristics of each of the one-dimensional time series data, each of the one-dimensional time series data is classified, and outlier time series data is determined in each of the one-dimensional time series data according to the classification results; the outlier time series data is used to generate the operation and maintenance anomaly information of the system to be detected.

[0005] Secondly, embodiments of this disclosure provide an outlier sequence detection device, comprising: The indicator acquisition unit is used to acquire the operation and maintenance indicators of the system to be tested; the operation and maintenance indicators include multiple one-dimensional time series data. The period determination unit is used to generate frequency domain data of the one-dimensional time series data for each of the one-dimensional time series data, and determine the data period of the one-dimensional time series data according to the frequency characteristics of the target frequency component in the frequency domain data. The feature extraction unit is used to convert each one-dimensional time series data into two-dimensional time series data according to the data period, and extract the time series features of the two-dimensional time series data as the classification features of the one-dimensional time series data. The data determination unit is used to classify each of the one-dimensional time series data according to the classification characteristics of each of the one-dimensional time series data, and to determine outlier time series data in each of the one-dimensional time series data according to the classification results; the outlier time series data is used to generate operation and maintenance anomaly information of the system to be detected.

[0006] Thirdly, embodiments of this disclosure provide an electronic device, including: a memory, a processor, and computer-executable instructions stored in the memory and executable on the processor, wherein the computer-executable instructions, when executed by the processor, implement the method described in the first aspect above.

[0007] Fourthly, embodiments of this disclosure provide a computer-readable storage medium for storing computer-executable instructions that, when executed by a processor, implement the method described in the first aspect above.

[0008] Fifthly, embodiments of this disclosure provide a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the method described in the first aspect above.

[0009] In one or more embodiments of this disclosure, firstly, the operation and maintenance indicators of the system to be tested are obtained; the operation and maintenance indicators include multiple one-dimensional time-series data; then, for each one-dimensional time-series data, frequency domain data of the one-dimensional time-series data is generated, and the data period of the one-dimensional time-series data is determined according to the frequency characteristics of the target frequency components in the frequency domain data; next, for each one-dimensional time-series data, the one-dimensional time-series data is converted into two-dimensional time-series data according to the data period, and the time-series features of the two-dimensional time-series data are extracted as the classification features of the one-dimensional time-series data; finally, each one-dimensional time-series data is classified according to the classification features of each one-dimensional time-series data, and outlier time-series data is determined in each one-dimensional time-series data according to the classification results; the outlier time-series data is used to generate operation and maintenance anomaly information of the system to be tested. As can be seen, through this embodiment, when the one-dimensional time-series data in the operation and maintenance indicators may or may not be periodic, frequency domain data of the one-dimensional time-series data is generated. By utilizing the frequency characteristics of the target frequency components in the frequency domain data, the data period related to the one-dimensional time-series data is determined, thereby realizing the discovery of the repetitive patterns of the one-dimensional time-series data in the time dimension. Furthermore, by converting the one-dimensional time-series data into two-dimensional time-series data according to the data period and extracting the time-series features of the two-dimensional time-series data, the time-series features can reflect both the internal characteristics of the one-dimensional time-series data in a single data period and the correlation characteristics of the one-dimensional time-series data between different data periods. The time-series features can provide a reference for the classification of one-dimensional time-series data, thereby accurately detecting outlier time-series data and improving the accuracy of anomaly detection in the system. Attached Figure Description

[0010] To more clearly illustrate the technical solutions in one or more embodiments of this disclosure, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments recorded in this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 This is a schematic flowchart illustrating an outlier sequence detection method according to an embodiment of the present disclosure. Figure 2 This is a flowchart illustrating the model training phase of another outlier sequence detection method provided in an embodiment of this disclosure. Figure 3 A flowchart illustrating the model inference stage of another outlier sequence detection method provided in an embodiment of this disclosure; Figure 4 This is a schematic diagram illustrating an example of an operation and maintenance indicator provided in one embodiment of the present disclosure; Figure 5 A schematic diagram of an energy density spectrum provided in an embodiment of this disclosure; Figure 6 An autocorrelation sequence diagram provided in one embodiment of this disclosure; Figure 7 This is a schematic diagram illustrating the detection results of outlier time-series data provided in an embodiment of this disclosure; Figure 8 This is a schematic diagram of an outlier sequence detection device provided in an embodiment of the present disclosure; Figure 9 This is a schematic diagram of the structure of an electronic device provided in one embodiment of the present disclosure. Detailed Implementation

[0012] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this disclosure, the technical solutions in one or more embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of the embodiments. Based on one or more embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of this document.

[0013] This disclosure provides an outlier sequence detection method and apparatus, which can improve the accuracy of anomaly detection in the system. The outlier sequence detection method can be applied to and implemented on a terminal device, including but not limited to laptops, tablets, desktop computers, set-top boxes, mobile devices (e.g., mobile phones, portable music players, personal digital assistants, dedicated messaging devices, portable gaming devices), smartphones, smart speakers, smartwatches, smart TVs, in-vehicle terminals, and other types of user terminals.

[0014] Figure 1 This is a schematic flowchart illustrating an outlier sequence detection method according to an embodiment of this disclosure. Figure 1 As shown, the process includes: Step S102: Obtain the operation and maintenance indicators of the system to be tested; the operation and maintenance indicators include multiple one-dimensional time series data.

[0015] Step S104: For each one-dimensional time series data, generate frequency domain data of the one-dimensional time series data, and determine the data period of the one-dimensional time series data based on the frequency characteristics of the target frequency components in the frequency domain data.

[0016] Step S106: For each one-dimensional time series data, convert the one-dimensional time series data into two-dimensional time series data according to the data period, and extract the time series features of the two-dimensional time series data as the classification features of the one-dimensional time series data.

[0017] Step S108: Classify each one-dimensional time series data according to its classification characteristics, and determine outlier time series data in each one-dimensional time series data according to the classification results; the outlier time series data is used to generate operation and maintenance anomaly information of the system to be detected.

[0018] In this embodiment, firstly, the operation and maintenance indicators of the system under test are obtained; the operation and maintenance indicators include multiple one-dimensional time series data; then, for each one-dimensional time series data, frequency domain data of the one-dimensional time series data is generated, and the data period of the one-dimensional time series data is determined according to the frequency characteristics of the target frequency components in the frequency domain data; next, for each one-dimensional time series data, the one-dimensional time series data is converted into two-dimensional time series data according to the data period, and the time series features of the two-dimensional time series data are extracted as the classification features of the one-dimensional time series data; finally, according to the classification features of each one-dimensional time series data, each one-dimensional time series data is classified, and outlier time series data are determined in each one-dimensional time series data according to the classification results; the outlier time series data is used to generate operation and maintenance anomaly information of the system under test. As can be seen, through this embodiment, when the one-dimensional time-series data in the operation and maintenance indicators may or may not be periodic, frequency domain data of the one-dimensional time-series data is generated. By utilizing the frequency characteristics of the target frequency components in the frequency domain data, the data period related to the one-dimensional time-series data is determined, thereby realizing the discovery of the repetitive patterns of the one-dimensional time-series data in the time dimension. Furthermore, by converting the one-dimensional time-series data into two-dimensional time-series data according to the data period and extracting the time-series features of the two-dimensional time-series data, the time-series features can reflect both the internal characteristics of the one-dimensional time-series data in a single data period and the correlation characteristics of the one-dimensional time-series data between different data periods. The time-series features can provide a reference for the classification of one-dimensional time-series data, thereby accurately detecting outlier time-series data and improving the accuracy of anomaly detection in the system.

[0019] In step S102 above, the operation and maintenance indicators of the system to be tested are obtained. The system to be tested can be any system with operation and maintenance requirements. The operation and maintenance indicators can be quantitative data that measures the system's operating status, efficiency, stability, and security, such as CPU utilization, memory utilization, bandwidth utilization, packet loss rate, storage utilization, etc. In this embodiment, the types of operation and maintenance indicators can be flexibly set according to requirements.

[0020] In step S102 above, the operation and maintenance indicators include multiple one-dimensional time series data. One-dimensional time series data refers to time series data composed of a series of timestamps and values, which is presented in a one-dimensional form.

[0021] In one example, the system under test runs on a service cluster comprising multiple nodes. The multiple one-dimensional time-series data points included in the operational metrics can be generated by different nodes within the same time period. For example, the service cluster comprises 30 nodes. The operational metric is CPU utilization, which includes 30 one-dimensional time-series data points, each corresponding to a node in the service cluster. These 30 one-dimensional time-series data points are all generated within the time period [X1, X2]. Specifically, one-dimensional time-series data point 1 represents multiple values ​​of CPU utilization for node 1 within the time period [X1, X2], with a data granularity of 1 minute. One-dimensional time-series data point 2 represents multiple values ​​of CPU utilization for node 2 within the time period [X1, X2], with a data granularity of 1 minute... One-dimensional time-series data point 30 represents multiple values ​​of CPU utilization for node 30 within the time period [X1, X2], with a data granularity of 1 minute.

[0022] In another example, the system under test runs on a single-node server, and the multiple one-dimensional time-series data included in the operation and maintenance metrics can be generated by the system under test at different time periods. For example, the operation and maintenance metric is the packet loss rate, which includes K one-dimensional time-series data, where K is an integer greater than 1. One-dimensional time-series data 1 represents: multiple values ​​of the packet loss rate of system 1 in the time period [T1, T2], with a data granularity of 5 minutes. One-dimensional time-series data 2 represents: multiple values ​​of the packet loss rate of system 1 in the time period [T3, T4], with a data granularity of 5 minutes... One-dimensional data 3 represents: multiple values ​​of the packet loss rate of system 1 in the time period [T5, T6], with a data granularity of 5 minutes.

[0023] The examples above are only for the purpose of understanding one-dimensional time series data. The time periods corresponding to multiple one-dimensional time series data can be the same or different. For multiple one-dimensional time series data, the nodes that generate the one-dimensional time series data can be the same or different, and are not limited to the two examples above.

[0024] In addition, after acquiring multiple one-dimensional time series data, each one-dimensional time series data can be preprocessed, and the preprocessed one-dimensional time series data can be used to perform subsequent steps S104-S108. Preprocessing methods include, but are not limited to: handling missing values, removing noise, resampling, etc.

[0025] In step S104 above, frequency domain data of the one-dimensional time series data is generated for each one-dimensional time series data. One-dimensional time series data can be considered as time-domain data, which is data that changes over time. Frequency domain data is data that changes with frequency after the time-domain data has been transformed using mathematical transformations. Mathematical transformations include, but are not limited to: Fourier transform, fast Fourier transform, short-time Fourier transform, wavelet transform, etc.

[0026] In one example, the frequency domain data of the one-dimensional time series data can be generated by performing a fast Fourier transform on the one-dimensional time series data to obtain the frequency domain data.

[0027] After executing step S102 above, multiple one-dimensional time series data can be obtained. For each one-dimensional time series data, the process of "generating frequency domain data of one-dimensional time series data" is executed. For example, the multiple one-dimensional time series data include time series data 1, time series data 2, and time series data 3. Frequency domain data of time series data 1 is generated to obtain frequency domain data 1; frequency domain data of time series data 2 is generated to obtain frequency domain data 2; and frequency domain data of time series data 3 is generated to obtain frequency domain data 3.

[0028] In step S104 above, for each one-dimensional time series data, the data period of the one-dimensional time series data is determined based on the frequency characteristics of the target frequency components in the frequency domain data. The frequency domain data may include one or more frequency components and the frequency characteristics of each frequency component. A frequency component refers to a fundamental signal of different frequencies obtained by decomposing the time domain data through mathematical transformations, such as a sine wave, cosine wave, etc. The number of target frequency components can be one or more, and each target frequency component is a frequency component included in the frequency domain data. The frequency characteristics of a frequency component include, but are not limited to, frequency, amplitude, energy, etc. The data period refers to the fixed time interval at which a certain feature or numerical pattern repeats in the one-dimensional time series data. The data period is the period related to the one-dimensional time series data determined based on the frequency characteristics of the target frequency components.

[0029] It is important to emphasize that one-dimensional time series data may or may not exhibit periodicity. Even if one-dimensional time series data does not show obvious periodicity as a whole, the period corresponding to the target frequency component in the frequency domain data can still be regarded as a potential period indirectly related to the one-dimensional time series data. This period can reflect the repetitive pattern of local fluctuations in the one-dimensional time series data.

[0030] In one embodiment, determining the data period of one-dimensional time series data based on the frequency characteristics of the target frequency component in the frequency domain data includes: determining the period of the target frequency component based on the frequency characteristics of the target frequency component, and determining the period of the target frequency component as the data period of the one-dimensional time series data.

[0031] In one example, the frequency feature includes frequency. The reciprocal of the frequency of the target frequency component is calculated to obtain the time period of the target frequency component. The time period of this target frequency component is then defined as the data period of the one-dimensional time series data.

[0032] In another example, the frequency feature includes frequency. Based on the frequency feature of the target frequency component, the period of the target frequency component is determined. This can be achieved by calculating the data point period of the target frequency component based on the number of data points in the one-dimensional time series data and the frequency of the target frequency component. The data point period of this target frequency component is then defined as the data period of the one-dimensional time series data.

[0033] The data point period can be understood as the number of data points that a target frequency component passes through to complete one full fluctuation in the first time series data. For example, if there are 100 data points in the one-dimensional time series data and the data point period of target frequency component 1 is 20, then for target frequency component 1, the one-dimensional time series data corresponds to 5 data point periods.

[0034] As can be seen, by using the period of the frequency component in one-dimensional time series data as the data related to the one-dimensional time series data through this embodiment, it is possible to discover the repetitive patterns of one-dimensional time series data in the time dimension even when the one-dimensional time series data may not have periodicity.

[0035] In one embodiment, the frequency domain data includes multiple frequency components and the frequency characteristics of each frequency component. Before determining the data period of the one-dimensional time series data based on the frequency characteristics of the target frequency component in the frequency domain data, the outlier sequence detection method further includes: determining the target frequency component among the frequency components based on the frequency characteristics of each frequency component. For example, the frequency characteristic is the frequency component intensity. The frequency components are sorted according to their frequency component intensity, and the k frequency components with the largest frequency component intensity are selected as the target frequency components based on the sorting result. k is an integer greater than or equal to 1. The greater the frequency component intensity, the stronger the influence of the frequency component on the one-dimensional time series data. For example, the frequency classification intensity can be represented by amplitude / energy.

[0036] In one example, the formula for converting one-dimensional time series data into amplitude using Fourier transform is as follows: A = Amp(FFT(X) 1D (1) Among them, X 1D For one-dimensional time series data, FFT stands for Fourier transform, Amp is used to calculate the amplitude of the corresponding frequency component, and A represents the amplitude of each frequency component in the frequency domain data of the one-dimensional time series data.

[0037] The k frequency components with the strongest frequency component intensity are selected as the target frequency components, which can be referred to the following formula: (2) Where A represents the amplitude of each frequency component in the frequency domain data of the one-dimensional time series data, argTopk represents the process of first selecting the k largest elements from a set of values ​​and then returning the corresponding indices or association identifiers of these k elements in the original set, T represents the number of data points in the one-dimensional time series data, f1 represents the frequency of the first selected frequency component, and f k This represents the frequency of the selected k-th frequency component.

[0038] In the frequency domain data of one-dimensional time series data, each frequency component has a unique corresponding frequency and amplitude. Therefore, the frequency of the selected frequency component can be determined based on its amplitude.

[0039] Based on the frequency characteristics of the target frequency components in the frequency domain data, the data period of the one-dimensional time series data can be determined using the following formula: (3) Where T represents the number of data points in the one-dimensional time series data, f i p represents the frequency of the selected i-th frequency component. i This represents the period of the selected i-th frequency component data point.

[0040] In this embodiment, the selected i-th frequency component can be used as the i-th target frequency component, and the data point period of the selected i-th frequency component can be used as one data period of the one-dimensional time series data. The number of target frequency components can be one or more, and the number of data periods can be one or more, with a one-to-one correspondence between target frequency components and data periods.

[0041] As can be seen, through this embodiment, when the frequency domain data includes multiple frequency components, the target frequency component with a relatively strong influence on the one-dimensional time series data is determined among each frequency component. Then, the frequency characteristics of the target frequency component are used to determine the data period related to the one-dimensional time series data, which is beneficial to discover the repetitive pattern of the one-dimensional time series data in the time dimension.

[0042] In one embodiment, the frequency domain data includes multiple frequency components and frequency characteristics of each frequency component. Before determining the data period of the one-dimensional time series data based on the frequency characteristics of the target frequency component in the frequency domain data, the outlier sequence detection method further includes: determining multiple candidate frequency components in each frequency component based on the frequency characteristics of each frequency component; generating an autocorrelation sequence of the candidate frequency data based on the time domain data corresponding to the candidate frequency components, and determining the peak spacing of the autocorrelation sequence; clustering the peak spacing corresponding to the candidate frequency components, and determining the target frequency component in each candidate frequency component based on the clustering results.

[0043] Based on the frequency characteristics of each frequency component, multiple candidate frequency components are determined from each frequency component. For example, if the frequency characteristic is amplitude, the frequency components are sorted according to their amplitude, and the k frequency components with the largest amplitudes are selected as candidate frequency components based on the sorting results. k is an integer greater than or equal to 1. The larger the amplitude, the stronger the influence of the frequency component on the one-dimensional time series data. Due to the similar concept, please refer to the corresponding description section of "determining the target frequency component from each frequency component based on its frequency characteristics" in the aforementioned embodiment.

[0044] After identifying multiple candidate frequency components, an inverse Fourier transform can be performed on each candidate frequency component to obtain its time-domain data.

[0045] Based on the time-domain data corresponding to the candidate frequency components, an autocorrelation sequence of the candidate frequency data is generated. This can be achieved by substituting the time-domain data into the autocorrelation function to obtain an ACF (Autocorrelation Function) sequence. There is a one-to-one correspondence between the candidate frequency data and the autocorrelation sequence.

[0046] In one example, the ACF calculation formula is as follows: (4) Among them, y t This represents the t-th data point in the time-domain data. The mean of the data points is represented by r, k represents the lag order, T represents the number of data points in the time domain data, and r represents the number of data points in the time domain data. k This represents the calculated autocorrelation function value.

[0047] Determining the peak spacing of an autocorrelation sequence can be achieved by extracting the peaks of the autocorrelation sequence and calculating the peak spacing. For example, by obtaining the peaks of an ACF sequence, we can obtain a peak list of the ACF sequence: [x1,x2,x3,……,xn]. Based on each peak in the peak list of the ACF sequence, a peak spacing list can be generated: [y1,y2,……,yn].

[0048] For each candidate frequency component, clustering is performed on the peak intervals corresponding to that candidate frequency component to obtain the clustering result for that candidate frequency component. There is a one-to-one correspondence between candidate frequency components and clustering results. Each clustering result can include at least one group. Each group includes one or more peak intervals, and each peak interval can be considered as a data point within that group.

[0049] In one example, clustering can use Mean Shift's mean center calculation formula, as shown below: (5) Among them, Mh (x) represents the calculated cluster centers, and x represents the data point currently being calculated. i w(x) represents the i-th data point in the dataset. i ) represents the weight of the i-th data point, n represents the number of data points, and G H This represents the kernel function, which can be a Gaussian kernel, etc.

[0050] Based on the clustering results, the target frequency component is determined among the candidate frequency components. This includes: for each candidate frequency component, identifying the cluster with the most data points in its clustering results; if the number of data points in the cluster with the most data points exceeds a preset threshold, it indicates that the candidate frequency component has strong periodicity and can be identified as a target frequency component; if the number of data points in the cluster with the most data points does not exceed the preset threshold, it indicates that the candidate frequency component has weak periodicity and can be identified as a non-target frequency component. The aforementioned periodicity and significance can be understood as whether the fluctuation can be stably and continuously repeated, and whether it conforms to the logic of a real-world scenario.

[0051] Furthermore, after determining the target frequency components, the period of each target frequency component can be calculated based on the cluster center of the cluster with the most data points in the clustering results and the data sampling interval. This period is then defined as one data period of the one-dimensional time series data. For example, if the cluster center is a peak-to-peak spacing of 288.1, multiplying the cluster center by the data sampling interval of 5 minutes yields a period of 24.01 hours.

[0052] As can be seen, through this embodiment, candidate frequency components are first obtained by screening each frequency component based on frequency characteristics, and then target frequency components are obtained by screening the candidate frequency components using the peak spacing of the autocorrelation sequence. This allows the target frequency components to satisfy both strong influence on one-dimensional time series data and strong periodicity. Furthermore, the frequency characteristics of the target frequency components are used to determine the data period related to the one-dimensional time series data, which is beneficial for uncovering stable and interpretable repetitive patterns in the time dimension of one-dimensional time series data.

[0053] In step S106 above, for each one-dimensional time series data, the one-dimensional time series data is converted into two-dimensional time series data according to the data period. There can be multiple one-dimensional time series data. For each one-dimensional time series data, the following process is performed: converting the one-dimensional time series data into two-dimensional time series data according to its data period. For each one-dimensional time series data, the data period corresponds one-to-one with the two-dimensional time series data.

[0054] In one example, when there is only one data period, the sequence is truncated and folded according to the length of the data period to form a two-dimensional matrix. Each column of the matrix represents the data of one period, and data from different time periods are arranged in different columns. When there are multiple data periods, a two-dimensional matrix corresponding to each data period is generated using the same method.

[0055] In one embodiment, for each one-dimensional time series data, the one-dimensional time series data is converted into two-dimensional time series data according to the data period, including: for each one-dimensional time series data, the one-dimensional time series data is segmented according to the data period to obtain multiple data segments; and the data segments are arranged in parallel according to the first dimension to obtain the two-dimensional time series data corresponding to the one-dimensional time series data.

[0056] One-dimensional time-series data can be segmented according to data periods to obtain multiple data segments. For example, if the one-dimensional time-series data includes 100 data points, data period 1 represents 20 data points, and data period 2 represents 50 data points, then segmenting the one-dimensional time-series data according to data period 1 yields 5 data segments, each containing 20 data points; segmenting the one-dimensional time-series data according to data period 2 yields 2 data segments, each containing 50 data points.

[0057] Arrange the data segments in parallel according to the first dimension to obtain the two-dimensional time series data corresponding to the one-dimensional time series data. The first dimension can be either the row dimension or the column dimension.

[0058] When the first dimension is a column dimension, in the process of arranging each data segment in parallel according to the first dimension to obtain the two-dimensional time series data corresponding to the one-dimensional time series data, each data segment can be transposed. According to the time order of each data segment, the transposed data segments are arranged from left to right to obtain the two-dimensional time series data.

[0059] For example, by dividing one-dimensional time-series data [a1, a2, a3, b1, b2, b3, c1, c2, c3] according to the data period, three data segments are obtained in chronological order: data segment 1 is [a1, a2, a3], data segment 2 is [b1, b2, b3], and data segment 3 is [c1, c2, c3].

[0060] Transpose data segment 1 to obtain Transpose data segment 2 to obtain Transpose data segment 3 to obtain Arrange the transposed data segments from left to right in chronological order to obtain two-dimensional time-series data. .

[0061] When the first dimension is a row dimension, in the process of arranging each data segment in parallel according to the first dimension to obtain the two-dimensional time series data corresponding to the one-dimensional time series data, each data segment can be arranged from top to bottom according to the time order to obtain the two-dimensional time series data.

[0062] For example, by dividing one-dimensional time-series data [a1, a2, a3, b1, b2, b3, c1, c2, c3] according to the data period, three data segments are obtained in chronological order: data segment 1 is [a1, a2, a3], data segment 2 is [b1, b2, b3], and data segment 3 is [c1, c2, c3].

[0063] Arrange the data segments chronologically from top to bottom to obtain two-dimensional time-series data. .

[0064] As can be seen, by dividing one-dimensional time-series data according to the data period in this embodiment, multiple data segments are obtained. By arranging each data segment in parallel according to the first dimension, two-dimensional time-series data is obtained. This allows data points with corresponding relationships in different data periods to be located in the same row or column, intuitively presenting the periodic pattern.

[0065] In step S106 above, the temporal features of the two-dimensional time series data are extracted as the classification features of the one-dimensional time series data. For any one-dimensional time series data, if the number of corresponding two-dimensional time series data is one, then the temporal features of the two-dimensional time series data are extracted, and the temporal features of the two-dimensional time series data are determined as the classification features of the one-dimensional time series data.

[0066] In the process of extracting temporal features from two-dimensional time-series data, various computer vision feature extraction backbone networks can be used. These networks include, but are not limited to, ResNet (Residual Neural Network), ResNeXt (Residual Network eXtension), Inception (Initial Convolutional Network), and attention-based models, among others.

[0067] Taking the Inception model as an example, the temporal features of two-dimensional time series data can be extracted using the following formula: (6) in, Representing two-dimensional time-series data, Inception represents the Inception model. Represents the temporal characteristics of two-dimensional time series data.

[0068] In this embodiment, the temporal features of the two-dimensional time series data can be a two-dimensional matrix. After extracting the temporal features of the two-dimensional time series data, these features can be decoupled and converted back from two-dimensional to one-dimensional. This conversion process corresponds to the aforementioned step of "converting one-dimensional time series data into two-dimensional time series data according to the data period". Specifically, the feature sequences folded according to different period lengths can be unfolded and then spliced ​​back into a one-dimensional sequence.

[0069] In one example, for one-dimensional time series data 1, it is segmented according to data period 1 to obtain multiple data segments. These data segments are then arranged in parallel along the first dimension to obtain the corresponding two-dimensional time series data. This two-dimensional time series data is a two-dimensional matrix with a rows and b columns, and each data segment is one row of this two-dimensional time series data. The time series features of the two-dimensional time series data are extracted; these features are also a two-dimensional matrix with a rows and b columns. These time series features are then split into multiple data segments, each of which is one row of the time series feature. These data segments are then concatenated in chronological order to form a one-dimensional time series data, resulting in one-dimensional time series data 1.

[0070] In one example, the temporal features can be converted from two dimensions to one dimension using the following formula: (7) in, This represents the temporal characteristics of two-dimensional time series data. "Reshape" indicates a reshaping operation on the temporal characteristics. The subscript "1" in "Reshape" indicates the number of rows after reshaping. " indicates the number of columns after reshaping, and Trunc indicates truncating the redundant parts. This represents a one-dimensional temporal feature.

[0071] In one embodiment, extracting the temporal features of two-dimensional time series data as classification features of one-dimensional time series data includes: for any one-dimensional time series data, if there are multiple two-dimensional time series data corresponding to the one-dimensional time series data, extracting the temporal features of each two-dimensional time series data respectively; fusing the temporal features of each two-dimensional time series data to obtain fused features, and using the fused features as classification features of one-dimensional time series data.

[0072] In one example, one-dimensional time series data 1 corresponds to two two-dimensional time series data: two-dimensional time series data 1 and two-dimensional time series data 2. Temporal features of two-dimensional time series data 1 are extracted to obtain feature 1, and temporal features of two-dimensional time series data 2 are extracted to obtain feature 2. Feature 1 and feature 2 are then fused to obtain the fused feature, which is used as the classification feature of the one-dimensional time series data.

[0073] As can be seen, this embodiment can fuse the time series features of multiple two-dimensional time series data when there are multiple two-dimensional time series data corresponding to one-dimensional time series data, and use the fused features as the classification features of one-dimensional time series data. This is beneficial for capturing the true patterns of multiple superimposed periods and avoiding the one-sidedness of a single period.

[0074] In one embodiment, the target frequency components correspond one-to-one with two-dimensional time series data; the time series features of each two-dimensional time series data are fused to obtain fused features, including: determining the weight information of each target frequency component based on the frequency features of each target frequency component of the one-dimensional time series data; and fusing the time series features of each two-dimensional time series data based on the weight information of each target frequency component to obtain fused features.

[0075] The weighting information of each target frequency component is determined based on its frequency characteristics in one-dimensional time series data. Frequency characteristics include, but are not limited to, amplitude, energy, etc.

[0076] In one example, feature fusion can be performed using the following formula: (8) (9) in, This represents the amplitude of the first target frequency component. This represents the amplitude of the k-th target frequency component, where k is the number of target frequency components. The Softmax function takes amplitude A as input and outputs the proportion of amplitudes with different intensities. For example, the Softmax function takes amplitude A as input and outputs the proportion of amplitudes with different intensities. As input, the output is the percentage of that amplitude. The Softmax function uses amplitude As input, the output is the percentage of that amplitude. .

[0077] Softmax is an activation function used for multi-class classification problems, often used in the output layer of neural networks. The Softmax function normalizes a K-dimensional vector containing arbitrary real numbers (where K is the number of classes) to a K-dimensional vector with values ​​in the range (0, 1), such that the sum of the elements in the vector is 1.

[0078] Represents the temporal characteristics of two-dimensional time series data.

[0079] The proportion of amplitudes with different intensities is determined as the weight information of each frequency component. Then, based on the weight information of each target frequency component, the temporal features of each two-dimensional time series data are fused to obtain the fused features.

[0080] Furthermore, after obtaining the fused features, considering that both the one-dimensional time series data and the one-dimensional time series features are numerical and have the same data structure, ensuring the consistency of network input, step S106 can be executed multiple times as needed to increase network depth and improve the expressive power of the features. For example, for each one-dimensional time series data, the one-dimensional time series data is converted into two-dimensional time series data 1 according to the data period, and time series feature 1 of two-dimensional time series data 1 is extracted; for each time series feature 1, time series feature 1 is converted into two-dimensional time series data 2 according to the data period, and time series feature 2 of two-dimensional time series data 2 is extracted; for each time series feature 2, time series feature 2 is converted into two-dimensional time series data 3 according to the data period, and time series feature 3 of two-dimensional time series data 3 is extracted; ...; for each time series feature (N-1), time series feature (N-1) is converted into two-dimensional time series data N according to the data period, and time series feature N of two-dimensional time series data N is extracted, and time series feature N is determined as the classification feature of the one-dimensional time series data. N is the set number of loops.

[0081] As can be seen, through this embodiment, the weight information used in the process of fusing various time series features comes from the frequency features of the target frequency components, which can make the periods with a large influence on the one-dimensional time series data receive high weights and the periods with a small influence receive low weights, thus avoiding secondary periods from interfering with the core patterns.

[0082] In step S108 above, each one-dimensional time series data is classified according to its classification characteristics; outlier time series data is identified from each one-dimensional time series data based on the classification results; and outlier time series data is used to generate operational anomaly information for the system to be detected. In this embodiment, a classification model can be pre-trained using clustering labels, thereby enabling the classification model to cluster input data. One-dimensional time series data corresponds one-to-one with classification features. For each one-dimensional time series data, the category in the classification result can be the cluster matched by the one-dimensional time series data, or the category can also indicate that there is no matching cluster for the one-dimensional time series data. After classifying multiple one-dimensional time series data, outlier time series data can be identified based on the number of data points in each cluster.

[0083] For example, if 100 one-dimensional time series data are classified, and the classification results of 95 of the one-dimensional time series data involve 3 clusters, while the remaining 5 one-dimensional time series data do not have a matching cluster, and the number of data points in the above 3 clusters is greater than a preset number threshold, then the above 95 one-dimensional time series data can be identified as non-outlier time series data, and the above 5 one-dimensional time series data without a matching cluster can be identified as outlier time series data.

[0084] For example, when classifying 100 one-dimensional time series data points, the classification results involve 3 clusters. If the number of data points in one cluster is less than a preset threshold, then the x one-dimensional time series data points corresponding to x data points in that cluster are all identified as outliers. x is an integer greater than or equal to 1.

[0085] Additionally, it's important to emphasize that outlier time series data and anomalous time series data are not the same concept. First, let's briefly introduce some related concepts: An outlier is a single data point that deviates significantly from most other data points in the dataset and does not conform to the overall data distribution pattern.

[0086] Outlier sequences are fragments in sequence data. They are a whole consisting of multiple data points arranged in order, which do not conform to the normal pattern of the entire long sequence.

[0087] Outlier time series data are segments within time series data that deviate from the normal time pattern in sequence data ordered by time.

[0088] Compared to anomalous time-series data, outlier time-series data is a more mathematical and statistical concept, referring to time-series data that deviates significantly from the overall distribution or trend of the data, as detected by statistical methods. Its identification relies more on the mathematical characteristics of the data itself than on the business context.

[0089] Compared to outlier time series data, anomalous time series data is a more business- and application-oriented concept, referring to time series data that does not conform to business expectations or normal operating patterns. Its identification is usually tied to specific scenarios rather than simply relying on mathematical statistics.

[0090] In operational scenarios, detecting outlier time-series data could indicate either actual business anomalies or simply normal data fluctuations. Further verification based on the specific scenario is necessary; it cannot be directly determined that the outlier data is abnormal. Therefore, outlier time-series data itself is not necessarily abnormal, but it can be used to generate operational anomaly information for the system under investigation. Accurately detecting outlier time-series data can reduce missed or false alarms, improving the accuracy of anomaly detection in the system.

[0091] In one embodiment, the temporal features of the two-dimensional time series data are extracted by a feature extraction network; the one-dimensional time series data are classified by a classifier; the outlier sequence detection method further includes: acquiring multiple one-dimensional sample time series data, and acquiring two-dimensional sample time series data corresponding to each one-dimensional sample time series data; for each one-dimensional sample time series data, extracting the sample temporal features of the two-dimensional sample time series data as sample classification features of the one-dimensional sample time series data by a feature extraction network; clustering each one-dimensional sample time series data according to the sample classification features of each one-dimensional sample time series data to obtain at least one first category label for each one-dimensional sample time series data; classifying each one-dimensional sample time series data according to the sample classification features of each one-dimensional sample time series data by a classifier to obtain at least one second category label for each one-dimensional sample time series data; and training the feature extraction network and the classifier according to the first category label and the second category label.

[0092] In this embodiment, extracting the temporal features of two-dimensional time series data as classification features of one-dimensional time series data can be achieved by using a feature extraction network to extract the temporal features of two-dimensional time series data as classification features of one-dimensional time series data. Furthermore, classifying each one-dimensional time series data point based on its classification features can be achieved by using a classifier to classify each one-dimensional time series data point based on its classification features.

[0093] Multiple one-dimensional sample time series data can be generated based on historical one-dimensional time series data of operation and maintenance indicators.

[0094] Obtaining the two-dimensional sample time series data corresponding to each one-dimensional sample time series data may include: generating frequency domain data of the one-dimensional sample time series data for each one-dimensional sample time series data; determining the data period of the one-dimensional sample time series data based on the frequency characteristics of the target frequency components in the frequency domain data; and converting the one-dimensional sample time series data into two-dimensional sample time series data for each one-dimensional sample time series data according to the data period. Due to the similar concept, please refer to the corresponding explanations of steps S104-S106 above.

[0095] For each one-dimensional sample time series data, a feature extraction network is used to extract the sample time series features of the two-dimensional sample time series data as the sample classification features of the one-dimensional sample time series data. Since the concept is similar, please refer to the corresponding explanation section of step S106 above.

[0096] Based on the sample classification characteristics of each one-dimensional sample time series data, clustering is performed on each one-dimensional sample time series data to obtain at least one first category label for each one-dimensional sample time series data.

[0097] In practice, clustering algorithms are used to cluster the sample classification features to obtain cluster labels, i.e., the aforementioned first category labels. Clustering algorithms include, but are not limited to, k-means, dbscan, etc. Here, the dbscan algorithm is used as an example for clustering. The dbscan clustering algorithm clusters the input features into several classes, and samples that do not belong to any class are outliers.

[0098] For example, the number of one-dimensional sample time series data is S. The cluster label of the first one-dimensional sample time series data is cluster 1, the cluster label of the second one-dimensional sample time series data is cluster 1, the cluster label of the third one-dimensional sample time series data is cluster 1, ..., and the cluster label of the Sth one-dimensional sample time series data is cluster 2.

[0099] Based on the classification features of each one-dimensional time series sample, a classifier is used to classify each one-dimensional time series sample, obtaining at least one second-class label for each sample. The second-class label can represent the cluster matched by the one-dimensional time series sample.

[0100] For example, if there are S one-dimensional time series data, the classification features of the S one-dimensional time series data are input into a classifier. The classifier classifies each one-dimensional time series data to obtain: the classification label of one-dimensional time series data 1 is "cluster 1", the classification label of one-dimensional time series data 2 is "cluster 2", and so on.

[0101] The training loss is generated based on the first and second class labels. This training loss is then used to update the model parameters of the feature extraction network and the classifier via backpropagation.

[0102] In one example, to avoid regression during loss function optimization—that is, to cluster all input sequences into one class to reduce loss—a clustering feedback mechanism can be used in the loss function. This mechanism uses the inverse of the number of data points in each cluster as a weight to weight the contribution of different input sequences to the loss value, thus explicitly constraining the distribution of input sequences among different clusters. The input sequences mentioned above refer to the sample classification features of one-dimensional time-series data. The optimized loss function is as follows: (10) in, These are the weighting coefficients in the loss function formula. θ represents the feature mapping performed by the feature extraction network, where θ is the parameter of the feature extraction network. is the classifier used to calculate the predicted label of the input features, and W is the classifier parameter; The input sequence contains the true labels obtained from the clustering results; L is the loss function, which can be negative log-softmax loss, etc. The number of sequences contained in the cluster to which the input sequence belongs; N is the total number of input sequences.

[0103] As can be seen, this embodiment can generate reliable labels for the input data of the classifier without providing any labeled data, and then use these labels to train the classifier. This not only saves labeling costs, but also enables the classifier to learn the ability to cluster. Furthermore, considering that the model parameters of the feature extraction network and the classifier are adjusted based on the training loss, it can avoid the features extracted by the feature extraction network from being disconnected from the features required for clustering, which is beneficial to improving classification accuracy.

[0104] In one embodiment, the outlier sequence detection method further includes: identifying the target node that generates the outlier time-series data and the associated nodes of the target node among the multiple service nodes included in the system to be detected; and performing anomaly analysis on the target node and the associated nodes to obtain operational anomaly information.

[0105] In this embodiment, the system to be detected may include multiple service nodes, each of which can generate corresponding one-dimensional time-series data. Each service node in the system to be detected may have one or more associated nodes. After identifying outlier time-series data from the various one-dimensional time-series data based on classification results, the target node that generated the outlier time-series data, and the associated nodes of the target node, can be identified from among the multiple service nodes included in the system to be detected.

[0106] Anomaly analysis for target nodes can involve analyzing their operational metrics to determine if they are the faulty nodes causing outlier time-series data. Similarly, anomaly analysis for associated nodes can involve analyzing their operational metrics to determine if they are the faulty nodes causing outlier time-series data. Operational anomaly information can include fault detection results for both the target and associated nodes.

[0107] In practical applications, if a service node malfunctions, in addition to abnormal fluctuations in its own operational metrics, it may also cause abnormal fluctuations in the operational metrics of multiple other service nodes associated with that service node. This embodiment can quickly narrow down the scope of locating the faulty node, improve the efficiency of identifying the faulty node, and thus improve operational efficiency.

[0108] In summary, through the embodiments of this disclosure, when the one-dimensional time-series data in the operation and maintenance indicators may or may not be periodic, frequency domain data of the one-dimensional time-series data is generated. By utilizing the frequency characteristics of the target frequency components in the frequency domain data, the data period related to the one-dimensional time-series data is determined, thereby realizing the discovery of the repetitive patterns of the one-dimensional time-series data in the time dimension. Furthermore, by converting the one-dimensional time-series data into two-dimensional time-series data according to the data period and extracting the time-series features of the two-dimensional time-series data, the time-series features can reflect both the internal characteristics of the one-dimensional time-series data in a single data period and the correlation characteristics of the one-dimensional time-series data between different data periods. These time-series features can provide a reference for the classification of one-dimensional time-series data, thereby accurately detecting outlier time-series data and improving the accuracy of anomaly detection in the system.

[0109] Based on the same technical concept, this disclosure also provides another method for outlier sequence detection, which can be referred to below. Figures 2-7 .

[0110] Figure 2 This is a flowchart illustrating the model training phase of another outlier sequence detection method provided in an embodiment of this disclosure.

[0111] Step S202: Obtain the original input time series.

[0112] The original input time series is the aforementioned one-dimensional time series data. For example, an operational metric like CPU utilization might include one-dimensional time series data from 30 nodes within the same 7-day time period, with a data granularity of 1 minute. (See reference...) Figure 4 As shown. Figure 4 This is a schematic diagram illustrating an example of an operation and maintenance indicator provided in one embodiment of this disclosure.

[0113] Step S204: Preprocess the input time series.

[0114] Since the granularity of data at different nodes in the original input time series may be inconsistent, the original input time series can be resampled at a 5-minute granularity to complete the data alignment.

[0115] Step S206: Extract the period of the sequence / feature.

[0116] Periodic extraction is performed on the preprocessed time series. Taking one-dimensional time series data of one node of CPU utilization as an example, the energy density spectrum of the one-dimensional time series data can be obtained using Fourier transform, which can be referenced. Figure 5 As shown. Figure 5 This is an example schematic diagram of an energy density spectrum provided for an embodiment of the present disclosure.

[0117] Step S208, periodicity significance verification.

[0118] The periodic significance of the top k frequency components with the highest energy in the energy density spectrum is verified. This is then transformed back to the time domain using inverse Fourier transform, and periods with strong significance are selected. This involves calculating the autocorrelation function of the time-domain data for the k frequency components to obtain the ACF sequence. The ACF sequence is shown below. Figure 6 As shown. Figure 6 An autocorrelation sequence diagram is provided for one embodiment of this disclosure.

[0119] In one example, the peak values ​​of the ACF sequence are obtained, resulting in a list of ACF sequence peak values ​​and a list of peak intervals. The peak interval list is clustered, resulting in two clusters with cluster centers [X1, X2] and cluster element counts [s1, s2]. A cluster threshold is set to half the total number of elements. If the number of cluster elements s1 in cluster [X1] exceeds the threshold, it is output as a significant period. The peak interval X1 is multiplied by the data sampling interval of 5 minutes to obtain the period.

[0120] Steps S206-S208 can be referred to the corresponding explanation of step S104 above.

[0121] Step S210: Convert the preprocessed sequence into a two-dimensional matrix according to period 1.

[0122] For example, the preprocessed time series can be transformed from one-dimensional to two-dimensional, and the time series can be folded according to the period "1 day". Since the original data contains 7 days of data, an x*7 two-dimensional matrix is ​​formed, where x represents the number of rows and 7 represents the number of columns. Each column of the matrix is ​​the data of one period, and the data of different time periods are arranged according to different columns.

[0123] Step S212: Extract two-dimensional sequence features to obtain a two-dimensional feature sequence.

[0124] For example, using the Inception model to extract features from the above two-dimensional sequence matrix, the resulting two-dimensional feature matrix still has a shape of x*7.

[0125] Step S214: The two-dimensional feature sequence is converted into a one-dimensional sequence.

[0126] For example, time-series features can be decoupled and transformed from two-dimensional to one-dimensional. The two-dimensional feature sequence can be expanded according to the daily cycle, that is, expanded column by column and then concatenated back to a one-dimensional sequence. The sequence length can be the product of x and 7.

[0127] Step S216: Convert the preprocessed sequence into a two-dimensional matrix according to a period of 2.

[0128] Step S218: Extract two-dimensional sequence features to obtain a two-dimensional feature sequence.

[0129] Step S220: The two-dimensional feature sequence is converted into a one-dimensional sequence.

[0130] Step S222: Convert the preprocessed sequence into a two-dimensional matrix according to a period of 3.

[0131] Step S224: Extract two-dimensional sequence features to obtain a two-dimensional feature sequence.

[0132] Step S226: The two-dimensional feature sequence is converted into a one-dimensional sequence.

[0133] Step S228: Feature fusion, integrating features into a single feature sequence according to weights.

[0134] Feature sequences extracted from different periods are fused, i.e., multiple output features are weighted and summed using the amplitude intensity of different periods as weights. Alternatively, if the target frequency component in the frequency domain data of one-dimensional time series data is only one, feature fusion is unnecessary and this step can be skipped.

[0135] Step S230: Has the number of loop layers been reached?

[0136] If yes, proceed to step S232; otherwise, return to step S206.

[0137] Steps S210-S214, S216-S220, S222-S226, S228 and S230 can be referred to the corresponding description of step S106 above.

[0138] Step S232: Input the feature sequence into the clustering module for clustering operation.

[0139] For example, the dbscan clustering algorithm was used to cluster 30 feature sequences of CPU utilization, and cluster labels were obtained. The clustering result showed that 28 of the 30 sequences belonged to the same cluster, while the remaining two sequences did not belong to any cluster and were considered outliers.

[0140] Step S234: Calculate the loss function based on the clustering results and data labels, and then backpropagate.

[0141] For example, a classifier can be trained using the clustering results of 30 node sequences representing CPU utilization metrics as labels. This involves using the feature sequence of each node as input to calculate the predicted label. Based on the predicted and true labels, a loss value is calculated, and the loss function updates the feature extraction network and classifier parameters via backpropagation.

[0142] In addition, after calculating the loss function, it can be determined whether the training termination condition is met based on the loss function. If the training termination condition is met, the training ends; otherwise, step S206 is executed.

[0143] Figure 3 This is a flowchart illustrating the model inference stage of another outlier sequence detection method provided in an embodiment of this disclosure.

[0144] Step S302: Obtain the original input time series.

[0145] The original input time series is the aforementioned one-dimensional time series data. For example, an operational metric like CPU utilization might include one-dimensional time series data from 30 nodes within the same 7-day time period, with a data granularity of 1 minute. (See reference...) Figure 4 As shown.

[0146] For details on this step, please refer to the corresponding explanation of step S102 mentioned above.

[0147] Step S304: Preprocess the input time series.

[0148] Since the granularity of data at different nodes in the original input time series may be inconsistent, the original input time series can be resampled at a 5-minute granularity to complete the data alignment.

[0149] Step S306: Extract the period of the sequence / feature.

[0150] Periodic extraction is performed on the preprocessed time series. Taking one-dimensional time series data of one node of CPU utilization as an example, the energy density spectrum of the one-dimensional time series data can be obtained using Fourier transform, which can be referenced. Figure 5 As shown.

[0151] Step S308, Periodicity Significance Verification.

[0152] The periodic significance of the top k frequency components with the highest energy in the energy density spectrum is verified. This is then transformed back to the time domain using inverse Fourier transform, and periods with strong significance are selected. This involves calculating the autocorrelation function of the time-domain data for the k frequency components to obtain the ACF sequence. The ACF sequence is shown below. Figure 6 As shown.

[0153] In one example, the peak values ​​of the ACF sequence are obtained, resulting in a list of ACF sequence peak values ​​and a list of peak intervals. The peak interval list is clustered, resulting in two clusters with cluster centers [X1, X2] and cluster element counts [s1, s2]. A cluster threshold is set to half the total number of elements. If the number of cluster elements s1 in cluster [X1] exceeds the threshold, it is output as a significant period. The peak interval X1 is multiplied by the data sampling interval of 5 minutes to obtain the period.

[0154] Steps S306-S308 can be referred to the corresponding explanations of step S104 above.

[0155] Step S310: Convert the preprocessed sequence into a two-dimensional matrix according to period 1.

[0156] For example, the preprocessed time series can be transformed from one-dimensional to two-dimensional, and the time series can be folded according to the period "1 day". Since the original data contains 7 days of data, a X1*7 two-dimensional matrix is ​​formed. Each column of the matrix is ​​the data of one period, and the data of different time periods are arranged in different columns.

[0157] Step S312: Extract two-dimensional sequence features to obtain a two-dimensional feature sequence.

[0158] Step S314: The two-dimensional feature sequence is converted into a one-dimensional sequence.

[0159] Step S316: Convert the preprocessed sequence into a two-dimensional matrix according to a period of 2.

[0160] Step S318: Extract two-dimensional sequence features to obtain a two-dimensional feature sequence.

[0161] Step S320: The two-dimensional feature sequence is converted into a one-dimensional sequence.

[0162] Step S322: Convert the preprocessed sequence into a two-dimensional matrix according to a period of 3.

[0163] Step S324: Extract two-dimensional sequence features to obtain a two-dimensional feature sequence.

[0164] Step S326: The two-dimensional feature sequence is converted into a one-dimensional sequence.

[0165] Step S328: Feature fusion, integrating features into a single feature sequence according to weights.

[0166] Feature sequences extracted from different periods are fused, i.e., multiple output features are weighted and summed using the amplitude intensity of different periods as weights. Alternatively, if the target frequency component in the frequency domain data of one-dimensional time series data is only one, feature fusion is unnecessary and this step can be skipped.

[0167] Step S330: Has the number of loop layers been reached?

[0168] If yes, proceed to step S332; otherwise, return to step S306.

[0169] Steps S310-S314, S316-S320, S322-S326, S328 and S330 can be referred to the corresponding description of step S106 above.

[0170] Step S332: Input the feature sequence into the classifier for classification processing.

[0171] Step S334: Determine whether the sequence is an outlier based on the classification results, and output the results.

[0172] For example, a trained classifier can directly determine which of the 30 node sequences representing CPU usage are outliers. Figure 7 This is a schematic diagram illustrating the detection results of outlier time series data provided in an embodiment of this disclosure, with reference to... Figure 7 As shown, there are 2 outlier sequences and 28 normal sequences among the 30 sequences.

[0173] Steps S332-S334 can be referred to the corresponding explanation of step S108 above.

[0174] Since the technical concept is the same, the description in this embodiment is relatively simple. For the relevant parts, please refer to the corresponding descriptions of the method embodiments provided above.

[0175] Figure 8 This is a schematic diagram of the structure of an outlier sequence detection device provided in an embodiment of the present disclosure, as shown below. Figure 8 As shown, the device includes: The indicator acquisition unit 802 is used to acquire the operation and maintenance indicators of the system to be tested; the operation and maintenance indicators include multiple one-dimensional time series data. The period determination unit 804 is used to generate frequency domain data of the one-dimensional time series data for each of the one-dimensional time series data, and determine the data period of the one-dimensional time series data according to the frequency characteristics of the target frequency component in the frequency domain data. The feature extraction unit 806 is used to convert the one-dimensional time series data into two-dimensional time series data according to the data period for each one-dimensional time series data, and extract the time series features of the two-dimensional time series data as the classification features of the one-dimensional time series data. The data determination unit 808 is used to classify each of the one-dimensional time series data according to the classification characteristics of each of the one-dimensional time series data, and to determine outlier time series data in each of the one-dimensional time series data according to the classification results; the outlier time series data is used to generate the operation and maintenance anomaly information of the system to be detected.

[0176] Optionally, the frequency domain data includes multiple frequency components and frequency characteristics of each frequency component; before determining the data period of the one-dimensional time series data based on the frequency characteristics of the target frequency component in the frequency domain data, the device further includes: a component determination unit and a spacing determination unit; The component determination unit is used to determine multiple candidate frequency components among the frequency components based on the frequency characteristics of each frequency component. The spacing determination unit is used to generate an autocorrelation sequence of the candidate frequency data based on the time-domain data corresponding to the candidate frequency components, and to determine the peak spacing of the autocorrelation sequence. The component determination unit is further configured to cluster the peak spacing corresponding to the candidate frequency components, and determine the target frequency component among the candidate frequency components based on the clustering results.

[0177] Optionally, when determining the data period of the one-dimensional time series data based on the frequency characteristics of the target frequency component in the frequency domain data, the period determination unit 804 performs the following steps: Based on the frequency characteristics of the target frequency component, the period of the target frequency component is determined, and the period of the target frequency component is determined as the data period of the one-dimensional time series data.

[0178] Optionally, when the feature extraction unit 806 converts the one-dimensional time-series data into two-dimensional time-series data according to the data period for each one-dimensional time-series data, it performs the following steps: For each of the one-dimensional time series data, the one-dimensional time series data is segmented according to the data period to obtain multiple data segments; Arrange the data segments in parallel according to the first dimension to obtain the two-dimensional time series data corresponding to the one-dimensional time series data.

[0179] Optionally, when the feature extraction unit 806 extracts the temporal features of the two-dimensional time series data as the classification features of the one-dimensional time series data, it performs the following steps: For any one of the one-dimensional time series data, if there are multiple two-dimensional time series data corresponding to the one-dimensional time series data, then the time series features of each of the two-dimensional time series data are extracted respectively. The temporal features of each of the two-dimensional time series data are fused to obtain fused features, which are then used as the classification features of the one-dimensional time series data.

[0180] Optionally, the target frequency components correspond one-to-one with the two-dimensional time series data; when the feature extraction unit 806 fuses the time series features of each of the two-dimensional time series data to obtain fused features, it performs the following steps: Based on the frequency characteristics of each target frequency component of the one-dimensional time series data, determine the weight information of each target frequency component; Based on the weight information of each target frequency component, the temporal features of each two-dimensional time series data are fused to obtain fused features.

[0181] Optionally, the temporal features of the two-dimensional time series data are extracted by a feature extraction network; the one-dimensional time series data are classified by a classifier; the device further includes: a data clustering unit, a data classification unit, and a training unit; The feature extraction unit 806 is also used to acquire multiple one-dimensional sample time series data, and to acquire two-dimensional sample time series data corresponding to each one-dimensional sample time series data. For each one-dimensional sample time series data, the feature extraction network is used to extract the sample time series features of the two-dimensional sample time series data as the sample classification features of the one-dimensional sample time series data. The data clustering unit is used to cluster each of the one-dimensional sample time series data according to the sample classification features of each of the one-dimensional sample time series data, so as to obtain at least one first category label of each of the one-dimensional sample time series data. The data classification unit is used to classify each of the one-dimensional sample time series data according to the sample classification features of each of the one-dimensional sample time series data through the classifier, so as to obtain at least one second category label for each of the one-dimensional sample time series data. The training unit is used to train the feature extraction network and the classifier based on the first category label and the second category label.

[0182] Optionally, the device further includes: a node determination unit and a node analysis unit; The node determination unit is used to determine, among the multiple service nodes included in the system to be detected, the target node that generates the outlier time series data and the associated node of the target node. The node analysis unit is used to perform anomaly analysis on the target node and the associated node to obtain the operation and maintenance anomaly information.

[0183] In this embodiment, when the one-dimensional time-series data in the operation and maintenance indicators may or may not be periodic, frequency domain data of the one-dimensional time-series data is generated. By utilizing the frequency characteristics of the target frequency components in the frequency domain data, the data period related to the one-dimensional time-series data is determined, thereby realizing the discovery of the repetitive patterns of the one-dimensional time-series data in the time dimension. Furthermore, by converting the one-dimensional time-series data into two-dimensional time-series data according to the data period, and extracting the time-series features of the two-dimensional time-series data, the time-series features can reflect both the internal characteristics of the one-dimensional time-series data in a single data period and the correlation characteristics of the one-dimensional time-series data between different data periods. These time-series features can provide a reference for the classification of one-dimensional time-series data, thereby accurately detecting outlier time-series data and improving the accuracy of anomaly detection in the system.

[0184] The outlier sequence detection device provided in one embodiment of this disclosure can implement the various processes in the aforementioned method embodiments and achieve the same functions and effects, which will not be repeated here.

[0185] Furthermore, one embodiment of this disclosure also provides an electronic device, Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure, such as... Figure 9 As shown, the device includes a memory 901, a processor 902, a bus 903, and a communication interface 904. The memory 901, processor 902, and communication interface 904 communicate via the bus 903. The communication interface 904 may include input / output interfaces, including but not limited to a keyboard, mouse, monitor, microphone, and loudspeaker.

[0186] Figure 9 In the processor 902, the memory 901 stores computer-executable instructions that can run on the processor 902. When the processor 902 executes the computer-executable instructions, the following process is implemented: Obtain the operation and maintenance indicators of the system to be tested; the operation and maintenance indicators include multiple one-dimensional time-series data. For each of the one-dimensional time series data, frequency domain data of the one-dimensional time series data is generated, and the data period of the one-dimensional time series data is determined according to the frequency characteristics of the target frequency component in the frequency domain data. For each of the one-dimensional time series data, the one-dimensional time series data is converted into two-dimensional time series data according to the data period, and the time series features of the two-dimensional time series data are extracted as the classification features of the one-dimensional time series data. Based on the classification characteristics of each of the one-dimensional time series data, each of the one-dimensional time series data is classified, and outlier time series data is determined in each of the one-dimensional time series data according to the classification results; the outlier time series data is used to generate the operation and maintenance anomaly information of the system to be detected.

[0187] In this embodiment, when the one-dimensional time-series data in the operation and maintenance indicators may or may not be periodic, frequency domain data of the one-dimensional time-series data is generated. By utilizing the frequency characteristics of the target frequency components in the frequency domain data, the data period related to the one-dimensional time-series data is determined, thereby realizing the discovery of the repetitive patterns of the one-dimensional time-series data in the time dimension. Furthermore, by converting the one-dimensional time-series data into two-dimensional time-series data according to the data period, and extracting the time-series features of the two-dimensional time-series data, the time-series features can reflect both the internal characteristics of the one-dimensional time-series data in a single data period and the correlation characteristics of the one-dimensional time-series data between different data periods. These time-series features can provide a reference for the classification of one-dimensional time-series data, thereby accurately detecting outlier time-series data and improving the accuracy of anomaly detection in the system.

[0188] An electronic device provided in one embodiment of this disclosure can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0189] Another embodiment of this disclosure also provides a computer-readable storage medium for storing computer-executable instructions that, when executed by a processor, implement the following process: Obtain the operation and maintenance indicators of the system to be tested; the operation and maintenance indicators include multiple one-dimensional time-series data. For each of the one-dimensional time series data, frequency domain data of the one-dimensional time series data is generated, and the data period of the one-dimensional time series data is determined according to the frequency characteristics of the target frequency component in the frequency domain data. For each of the one-dimensional time series data, the one-dimensional time series data is converted into two-dimensional time series data according to the data period, and the time series features of the two-dimensional time series data are extracted as the classification features of the one-dimensional time series data. Based on the classification characteristics of each of the one-dimensional time series data, each of the one-dimensional time series data is classified, and outlier time series data is determined in each of the one-dimensional time series data according to the classification results; the outlier time series data is used to generate the operation and maintenance anomaly information of the system to be detected.

[0190] In this embodiment, when the one-dimensional time-series data in the operation and maintenance indicators may or may not be periodic, frequency domain data of the one-dimensional time-series data is generated. By utilizing the frequency characteristics of the target frequency components in the frequency domain data, the data period related to the one-dimensional time-series data is determined, thereby realizing the discovery of the repetitive patterns of the one-dimensional time-series data in the time dimension. Furthermore, by converting the one-dimensional time-series data into two-dimensional time-series data according to the data period, and extracting the time-series features of the two-dimensional time-series data, the time-series features can reflect both the internal characteristics of the one-dimensional time-series data in a single data period and the correlation characteristics of the one-dimensional time-series data between different data periods. These time-series features can provide a reference for the classification of one-dimensional time-series data, thereby accurately detecting outlier time-series data and improving the accuracy of anomaly detection in the system.

[0191] The computer-readable storage medium includes read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc.

[0192] The computer-readable storage medium provided in one embodiment of this disclosure can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0193] Another embodiment of this disclosure also provides a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the following process: Obtain the operation and maintenance indicators of the system to be tested; the operation and maintenance indicators include multiple one-dimensional time-series data. For each of the one-dimensional time series data, frequency domain data of the one-dimensional time series data is generated, and the data period of the one-dimensional time series data is determined according to the frequency characteristics of the target frequency component in the frequency domain data. For each of the one-dimensional time series data, the one-dimensional time series data is converted into two-dimensional time series data according to the data period, and the time series features of the two-dimensional time series data are extracted as the classification features of the one-dimensional time series data. Based on the classification characteristics of each of the one-dimensional time series data, each of the one-dimensional time series data is classified, and outlier time series data is determined in each of the one-dimensional time series data according to the classification results; the outlier time series data is used to generate the operation and maintenance anomaly information of the system to be detected.

[0194] In this embodiment, when the one-dimensional time-series data in the operation and maintenance indicators may or may not be periodic, frequency domain data of the one-dimensional time-series data is generated. By utilizing the frequency characteristics of the target frequency components in the frequency domain data, the data period related to the one-dimensional time-series data is determined, thereby realizing the discovery of the repetitive patterns of the one-dimensional time-series data in the time dimension. Furthermore, by converting the one-dimensional time-series data into two-dimensional time-series data according to the data period, and extracting the time-series features of the two-dimensional time-series data, the time-series features can reflect both the internal characteristics of the one-dimensional time-series data in a single data period and the correlation characteristics of the one-dimensional time-series data between different data periods. These time-series features can provide a reference for the classification of one-dimensional time-series data, thereby accurately detecting outlier time-series data and improving the accuracy of anomaly detection in the system.

[0195] The computer program product in this disclosure embodiment can implement the various processes of the above-described outlier sequence detection method embodiment and achieve the same effect and function, which will not be repeated here.

[0196] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-readable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0197] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0198] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0199] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0200] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0201] Memory may include non-persistent storage in computer-readable storage media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable storage media.

[0202] Computer-readable storage media include both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer-readable storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable storage media does not include transient media, such as modulated data signals and carrier waves.

[0203] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0204] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0205] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for detecting outlier sequences, characterized in that, include: Obtain the operation and maintenance indicators of the system to be tested; the operation and maintenance indicators include multiple one-dimensional time-series data. For each of the one-dimensional time series data, frequency domain data of the one-dimensional time series data is generated, and the data period of the one-dimensional time series data is determined according to the frequency characteristics of the target frequency component in the frequency domain data. For each of the one-dimensional time series data, the one-dimensional time series data is converted into two-dimensional time series data according to the data period, and the time series features of the two-dimensional time series data are extracted as the classification features of the one-dimensional time series data. Based on the classification characteristics of each of the one-dimensional time series data, each of the one-dimensional time series data is classified, and outlier time series data is determined in each of the one-dimensional time series data according to the classification results. The out-of-group time-series data is used to generate operational anomaly information for the system under test.

2. The method according to claim 1, characterized in that, The frequency domain data includes multiple frequency components and frequency characteristics of each frequency component; before determining the data period of the one-dimensional time series data based on the frequency characteristics of the target frequency component in the frequency domain data, the method further includes: Based on the frequency characteristics of each frequency component, multiple candidate frequency components are determined among each frequency component; Based on the time-domain data corresponding to the candidate frequency components, an autocorrelation sequence of the candidate frequency data is generated, and the peak spacing of the autocorrelation sequence is determined. Cluster the peak spacings corresponding to the candidate frequency components, and determine the target frequency component from among the candidate frequency components based on the clustering results.

3. The method according to claim 1, characterized in that, Determining the data period of the one-dimensional time series data based on the frequency characteristics of the target frequency components in the frequency domain data includes: Based on the frequency characteristics of the target frequency component, the period of the target frequency component is determined, and the period of the target frequency component is determined as the data period of the one-dimensional time series data.

4. The method according to claim 1, characterized in that, The step of converting each one-dimensional time-series data into two-dimensional time-series data according to the data period includes: For each of the one-dimensional time series data, the one-dimensional time series data is segmented according to the data period to obtain multiple data segments; Arrange the data segments in parallel according to the first dimension to obtain the two-dimensional time series data corresponding to the one-dimensional time series data.

5. The method according to claim 1, characterized in that, The step of extracting the temporal features of the two-dimensional time series data as the classification features of the one-dimensional time series data includes: For any one of the one-dimensional time series data, if there are multiple two-dimensional time series data corresponding to the one-dimensional time series data, then the time series features of each of the two-dimensional time series data are extracted respectively. The temporal features of each of the two-dimensional time series data are fused to obtain fused features, which are then used as the classification features of the one-dimensional time series data.

6. The method according to claim 5, characterized in that, The target frequency components correspond one-to-one with the two-dimensional time series data; the fusion of the time series features of each of the two-dimensional time series data to obtain fused features includes: Based on the frequency characteristics of each target frequency component of the one-dimensional time series data, determine the weight information of each target frequency component; Based on the weight information of each target frequency component, the temporal features of each two-dimensional time series data are fused to obtain fused features.

7. The method according to claim 1, characterized in that, The temporal features of the two-dimensional time-series data are extracted using a feature extraction network. The one-dimensional time-series data is classified using a classifier; the method further includes: Multiple one-dimensional sample time series data are obtained, and two-dimensional sample time series data corresponding to each one-dimensional sample time series data are obtained. For each one-dimensional sample time series data, the sample time series features of the two-dimensional sample time series data are extracted by the feature extraction network as the sample classification features of the one-dimensional sample time series data. Based on the sample classification features of each one-dimensional sample time series data, clustering is performed on each one-dimensional sample time series data to obtain at least one first category label for each one-dimensional sample time series data. Based on the sample classification features of each of the one-dimensional sample time series data, the classifier classifies each of the one-dimensional sample time series data to obtain at least one second category label for each of the one-dimensional sample time series data. The feature extraction network and the classifier are trained based on the first category label and the second category label.

8. The method according to claim 1, characterized in that, The method further includes: Among the multiple service nodes included in the system to be detected, the target node that generates the outlier time-series data and the associated node of the target node are determined; Anomaly analysis and processing are performed on the target node and the associated node to obtain the operation and maintenance anomaly information.

9. An outlier sequence detection device, characterized in that, include: The indicator acquisition unit is used to acquire the operation and maintenance indicators of the system to be tested; the operation and maintenance indicators include multiple one-dimensional time series data. The period determination unit is used to generate frequency domain data of the one-dimensional time series data for each of the one-dimensional time series data, and determine the data period of the one-dimensional time series data according to the frequency characteristics of the target frequency component in the frequency domain data. The feature extraction unit is used to convert each one-dimensional time series data into two-dimensional time series data according to the data period, and extract the time series features of the two-dimensional time series data as the classification features of the one-dimensional time series data. The data determination unit is used to classify each of the one-dimensional time series data according to the classification characteristics of each of the one-dimensional time series data, and to determine outlier time series data in each of the one-dimensional time series data according to the classification results. The out-of-group time-series data is used to generate operational anomaly information for the system under test.

10. An electronic device, characterized in that, The method includes a memory and a processor, wherein the memory stores computer-executable instructions that, when executed on the processor, implement the method described in any one of claims 1-8.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions that, when executed by a processor, implement the method described in any one of claims 1-8.

12. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-8.